Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-5301

25
FAUCET Score

CVE-2026-5301 is a stored cross-site scripting (XSS) vulnerability in CoolerControl's log viewer component affecting versions prior to 4.0.0. The flaw enables unauthenticated attackers to inject malicious JavaScript code into log entries, which is then executed when the logs are viewed. This vulnerability permits complete service compromise through stored XSS payloads that persist in log data. The attack has a CVSS score of 6.1 (Medium severity) with a network-based attack vector requiring no authentication or special privileges, though user interaction is necessary to trigger the payload. The vulnerability could result in limited confidentiality and integrity impacts with the ability to affect systems beyond the immediate application boundary. The EPSS score of 0.00028 indicates minimal observed exploitation prevalence in the wild. This vulnerability is not currently listed on the Known Exploited Vulnerabilities (KEV) catalog and is marked as inactive on industry hot lists, suggesting no active exploitation campaigns are documented at this time. While the FAUCET risk score of 43.0/100 suggests moderate concern, the low EPSS prevalence indicates limited real-world exploitation activity or publicly available exploit code. Organizations running CoolerControl versions below 4.0.0 should prioritize patching to address the unauthenticated XSS vector.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.0.0CPE matchmatch criteria
cpe:2.3:a:coolercontrol:coolercontrold:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.6HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
HIGH
Availability Impact
LOW
Exploitability Score
2.8
Impact Score
4.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.28%
Probability of exploitation in next 30 days
EPSS Percentile
19.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0028 is in the 20th percentile among its peer group of 26,219 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

gitlab.com / coolercontrol/coolercontrol/-/blob/2.0.0/coolercontrol-ui/src/views/AppInfoView.vue
Product
gitlab.com / coolercontrol/coolercontrol/-/blob/3.1.1/coolercontrol-ui/src/views/AppInfoView.vue
Product
gitlab.com / coolercontrol/coolercontrol/-/releases/4.0.0
Release Notes